Skip to content

Where the code comes from

inbuxa started as a fork of Stalwart, and its server and console descend from it. Since then it has gone its own way. This page is the record of what was taken, what was left out, and how the rest was written. Everything on it can be checked against the public repositories it links to.

Each piece, and what it started from

Piece Started from License
inbuxa server The Stalwart mail server, v0.16.22, taken under the AGPL AGPL-3.0-only
inbuxa Admin Stalwart's web interface, v1.0.11, taken under the AGPL AGPL-3.0-only
inbuxa Webmail ihasmail, a Coffey Labs project AGPL-3.0-or-later
inbuxa installer ihasmail-oneshot, a Coffey Labs project AGPL-3.0-or-later

Upstream's copyright notices stay on every file they cover. Every file in the server and the console that was changed for inbuxa carries a notice saying so, and both repositories' checks fail a change that leaves one out.

What is taken, and what is left out

Stalwart publishes its code under two licenses: the AGPL, and a commercial license for some files and parts of files, which it marks LicenseRef-SEL. inbuxa takes the AGPL code only.

  • Snapshots, not history. Each import is a snapshot of one tagged release. Upstream's git history is never brought in.
  • Stripped before it is committed. A script removes every file and passage marked for the commercial license only, then checks that no marker is left. It reads the markers, not the code between them.
  • A report for every import. What was removed, file by file, is committed beside the code: v0.16.22, v0.16.23 and v0.16.24. The first removed 63 files outright, and 117 marked passages from 50 others.

Features rebuilt clean-room

Nine features weren't in the AGPL code, so they were written again from nothing, under rules set down before any of them was started (SPEC.md §3):

  • Specs come first, from public sources only: public documentation, the RFCs, the published schema (taken under the AGPL) and the observed behavior of a running server.
  • Code comes from the specs only. Whoever implements a feature works from its written spec, and must never have seen the commercially licensed code.
  • Every spec is dated, committed before its code, and names its sources. Where a source doesn't settle a behavior, the spec records a decision of its own rather than filling the gap from memory.
Feature Spec, with its sources Spec committed Built
Tenants multi-tenancy.md 18 Sep 2026 18 Sep 2026
Masked addresses masked-email.md 18 Sep 2026 18 Sep 2026
Undelete undelete.md 18 Sep 2026 18 Sep 2026
Branding and templates branding-and-templates.md 18 Sep 2026 18 Sep 2026
The language model's opinion on spam ai-spam-classification.md 18 Sep 2026 19 Sep 2026
Monitoring history, live tracing and alerts monitoring.md 18 Sep 2026 19 Sep 2026
SCIM provisioning scim.md 18 Sep 2026 19 Sep 2026
Scale-out storage scale-out-storage.md 18 Sep 2026 19 Sep 2026
A directory per domain per-domain-directories.md 18 Sep 2026 19 Sep 2026

License keys and seat limits weren't rebuilt. They were removed.

Features that are our own

Much of what inbuxa does now has no upstream counterpart, and was designed here from the start: the audit log, legal holds and locked accounts, data loss prevention and mail flow rules, journaling, the personal-data inventory and compliance officer roles, shared mailboxes, and the security to-do list. Specs for several, such as data loss prevention and journaling, are in the same folder. inbuxa Webmail and the installer were never derived from Stalwart's code.

How it is checked

  • Scans of the whole history. On 18 and 19 September 2026, every commit of every branch of the server, the console and the webmail was searched for a file licensed only under the commercial license, and for any marked passage. None was found.
  • Each later import goes through the same strip and gets its own report.

Security fixes

inbuxa keeps tracking Stalwart's security advisories for as long as its code stays close enough for a fix to apply.


Stalwart is a trademark of Stalwart Labs LLC. inbuxa is not affiliated with or endorsed by Stalwart Labs.